Vulnerability Description
The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticated users to overwrite a site-wide WP Travel Engine WordPress plugin before 6.8.2 option (the public nonce that gates the action is served to anonymous visitors).
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-12500?
CVE-2026-12500 is a vulnerability with a CVSS score of 7.5 (HIGH). The WP Travel Engine WordPress plugin before 6.8.2 does not perform a capability check on an AJAX action that updates a WP Travel Engine WordPress plugin before 6.8.2 option, allowing unauthenticate...
How severe is CVE-2026-12500?
CVE-2026-12500 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-12500?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.